CVE-2024-24758

LOW3.9EPSS 0.28%

Undici proxy-authorization header not cleared on cross-origin redirect in fetch

Published: 2/16/2024Modified: 5/2/2024
Also known as:GHSA-3787-6prv-h9w3

Description

### Impact Undici already cleared Authorization headers on cross-origin redirects, but did not clear `Proxy-Authorization` headers. ### Patches This is patched in v5.28.3 and v6.6.1 ### Workarounds There are no known workarounds. ### References - https://fetch.spec.whatwg.org/#authentication-entries - https://github.com/nodejs/undici/security/advisories/GHSA-wqq4-5wpv-mx2g

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1LOW3.9CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L

References (10)